Classification: Malicious
file is a malicious file sample. Linked to Turla, Oilrig activity. Reported by 2 threat sources, last seen 2023-03-18. Detected by 76 antivirus engines.
Detection summary
- 76 antivirus detections (72% detection ratio)
- 0 IDS alerts
- 1 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2023-03-18 17:00:03 |
2023-03-18 17:00:03 |
|
|
| Turla |
Maltiverse |
2023-03-03 04:26:37 |
2023-03-04 19:42:05 |
malicious-activity
|
G0010 Turla
|
| OilRig |
Maltiverse |
2023-03-03 04:26:38 |
2023-03-04 19:41:50 |
malicious-activity
|
G0049 OilRig
|
Tags
apt
hacktool
metasploit
meterpreter
apt34
Sample information
- Filenames
- file
- File type
- PE32 executable (console) Intel 80386 Mono/.Net as ...
- Size
- 18944 bytes
- MD5
6e4b7f13178ebc04304ee2b5ee646d09
- SHA-1
663a78cb5e6f3ab54cd0d3f67bd8c9545b341d6f
- SHA-256
24fe571f3066045497b1d8316040734c81c71dcb1747f1d7026cda810085fad7
- First indexed
- 2023-03-04 19:41:50
- Last updated
- 2025-11-24 02:33:22
Antivirus detections
| Engine | Detection |
| Lionic | Trojan.MSIL.Agent.4!c |
| DrWeb | Trojan.MulDrop9.16076 |
| MicroWorld-eScan | Trojan.Autoruns.GenericKD.41655882 |
| FireEye | Trojan.Autoruns.GenericKD.41655882 |
| ALYac | Trojan.MSIL.Agent |
| Cylance | Unsafe |
| Zillya | Trojan.Agent.Win32.1109058 |
| Sangfor | Trojan.MSIL.Onoynah.mt |
| K7AntiVirus | Trojan ( 00551ac81 ) |
| Alibaba | Trojan:MSIL/Turla.984123c1 |
| K7GW | Trojan ( 00551ac81 ) |
| Cybereason | malicious.3178eb |
| BitDefenderTheta | Gen:NN.ZemsilF.34266.bm0@ayBsFFc |
| Symantec | Backdoor.Trojan |
| ESET-NOD32 | a variant of MSIL/Turla.I |
| Paloalto | generic.ml |
| Cynet | Malicious (score: 99) |
| Kaspersky | HEUR:Trojan.MSIL.Agent.gen |
| BitDefender | Trojan.Autoruns.GenericKD.41655882 |
| NANO-Antivirus | Trojan.Win32.Drop.frxjtr |
| Avast | Win32:Trojan-gen |
| Tencent | Msil.Trojan.Agent.Wqnj |
| Ad-Aware | Trojan.Autoruns.GenericKD.41655882 |
| Emsisoft | Trojan.Autoruns.GenericKD.41655882 (B) |
| Comodo | Malware@#258ohdapn0w5s |
| VIPRE | Trojan.Win32.Generic!BT |
| TrendMicro | TROJ_GEN.R002C0DG821 |
| McAfee-GW-Edition | BackDoor.gen.b |
| Sophos | Mal/Generic-S |
| GData | Trojan.Autoruns.GenericKD.41655882 |
| Avira | TR/Agent.jcdsz |
| MAX | malware (ai score=100) |
| Antiy-AVL | Trojan/MSIL.Agent |
| Kingsoft | Win32.Troj.Undef.(kcloud) |
| Arcabit | Trojan.Autoruns.Generic.D27B9E4A |
| ZoneAlarm | HEUR:Trojan.MSIL.Agent.gen |
| Microsoft | Trojan:MSIL/Onoynah |
| AhnLab-V3 | Trojan/Win32.Agent.C3331654 |
| McAfee | BackDoor.gen.b |
| VBA32 | TScope.Trojan.MSIL |
| Malwarebytes | Malware.AI.4173385363 |
| TrendMicro-HouseCall | TROJ_GEN.R002C0DG821 |
| Yandex | Trojan.Agent!sPwyjrnKxGs |
| Ikarus | APT34.Turla.Exange.Bot |
| Fortinet | MSIL/Agent.O!tr |
| Webroot | W32.Trojan.Gen |
| AVG | Win32:Trojan-gen |
| Panda | Trj/GdSda.A |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Antiy-AVL | Trojan[APT]/MSIL.Turla |
| Arcabit | IL:Trojan.MSILZilla.D7897 |
| BitDefender | IL:Trojan.MSILZilla.30871 |
| Bkav | W32.AIDetectMalware.CS |
| CAT-QuickHeal | Trojan.Ghanarava.1710488771646d09 |
| CTX | exe.trojan.msilzilla |
| DeepInstinct | MALICIOUS |
| Elastic | malicious (moderate confidence) |
| Emsisoft | IL:Trojan.MSILZilla.30871 (B) |
| F-Secure | Trojan.TR/Agent.jcdsz |
| FireEye | Generic.mg.6e4b7f13178ebc04 |
| GData | IL:Trojan.MSILZilla.30871 |
| Google | Detected |
| Kingsoft | malware.kb.c.991 |
| Lionic | Trojan.Win32.Turla.4!c |
| Malwarebytes | Generic.Malware/Suspicious |
| MaxSecure | Trojan.Malware.8703358.susgen |
| MicroWorld-eScan | IL:Trojan.MSILZilla.30871 |
| Rising | Trojan.Agent!8.B1E (CLOUD) |
| Sangfor | Backdoor.Win32.Turla.ulxpg |
| Skyhigh | BackDoor.gen.b |
| Symantec | Backdoor.Whisperer |
| Tencent | Msil.Trojan.Agent.Gtgl |
| VIPRE | IL:Trojan.MSILZilla.30871 |
| Varist | W32/ABTrojan.AZSC-8602 |
| Xcitium | Malware@#258ohdapn0w5s |
| alibabacloud | Trojan:MSIL/Turla.I |
Process list
| Name | Command line |
| file.exe | |